Secrets
API keys and settings your agents use by name, without reading them. Values are encrypted on your machines with your vault key; 0bridge stores only ciphertext.
Move a .env in#
0b secret import .env --dry-run # list what would move; nothing is stored
0b secret import .env --only A,B # move just the names you pick
0b exec -- bun dev
--dry-run lists each name (never a value) with its guessed kind, whether it would replace a value already in the vault, and whether it points at this machine (localhost, 127.0.0.1): a local database or dev server address that every other machine would get too. Those usually stay in the file. Without --only, every line moves.
0b exec runs a command with the repo's values (and your global ones) as environment variables, plus ZEROBRIDGE_ENV (the environment the values came from: dev, or prod with --env prod) so a script can tell it runs under 0bridge. When a program reads its output, as an agent does, secrets show as ***; in your own terminal they print as they are. Each value is a secret (hidden) or a variable (like PORT, shown as is); the guess can be changed with 0b secret mark.
Or let your agent do it#
On the dashboard's Secrets page, copy the prompt and paste it into Claude Code, Codex or Cursor in the repo. The agent lists what's in the .env files without printing any value, asks which to move, and moves those.
Switch off, note#
0b secret off NAMEkeeps a value but stops giving it to commands, instead of commenting a line out of .env. A repo value that's off lets the global one through.0b secret note NAME "acme org token, expires 2027-03"explains a value. Notes are encrypted like the values, and0b secret listshows them.
Production#
Values in the prod environment need your approval in the browser (your passkey, or a fresh sign-in if you have none) before a machine can use or change them, for 30 minutes, 2 hours or 8 hours. Run it with 0b exec --env prod -- <cmd>.
New machine#
0b vault unlock
Approve it on the dashboard with your passkey, or on another machine with 0b vault approve. Or type your recovery key: 0b vault unlock --recovery-key. Keep the recovery key in your password manager; 0bridge can't recover it.